✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Anubis Ransomware Exploits Citrix Bleed 2 Vulnerability in 2026
In early July 2026, the Anubis ransomware group exploited a critical vulnerability known as Citrix Bleed 2 (CVE-2025-5777) in Citrix NetScaler appliances to gain unauthorized access to enterprise networks. This flaw allowed attackers to bypass multi-factor authentication by stealing session tokens, leading to the compromise of 91 organizations across sectors such as healthcare, financial services, manufacturing, and technology. The attackers utilized legitimate remote management tools to maintain persistence and evade detection, culminating in the deployment of ransomware that encrypted critical data and disrupted operations. This incident underscores the persistent threat posed by unpatched vulnerabilities and the sophisticated tactics employed by ransomware groups. The exploitation of Citrix Bleed 2 highlights the importance of timely patch management and the need for comprehensive monitoring of remote access tools to detect and prevent unauthorized activities.
2 weeks ago
Kill Chain
Urgent Alert: Widespread Scanning Targets MCP Servers and AI Assistant Credentials
In July 2026, security researchers identified a widespread scanning campaign targeting Model Context Protocol (MCP) servers and AI assistant credential files. Attackers systematically probed internet-facing systems for exposed MCP endpoints and configuration files associated with AI development tools, aiming to exploit misconfigurations and gain unauthorized access. This reconnaissance activity underscores the critical need for organizations to secure their AI infrastructure against emerging threats. The incident highlights a growing trend of attackers focusing on AI-related assets, exploiting the rapid adoption of AI technologies and potential security oversights. Organizations must proactively implement robust security measures to protect sensitive AI systems and data from evolving cyber threats.
2 weeks ago
Kill Chain
RedHook Android Malware Exploits Wireless ADB for Unauthorized Access
In July 2026, cybersecurity researchers identified a new variant of the RedHook Android malware that exploits the Wireless Android Debug Bridge (ADB) feature to gain shell-level access without a computer connection. By deceiving users into granting Accessibility permissions, RedHook enables Developer Options and activates Wireless Debugging, allowing it to connect to the device's ADB service via the loopback interface. This grants the malware elevated privileges, enabling it to stream screens, intercept keystrokes, automate UI interactions, and steal credentials. The attack does not require device rooting, making it effective across all Android devices where users approve the Accessibility Service request. This incident underscores the evolving sophistication of mobile malware, highlighting the need for heightened vigilance among Android users. The exploitation of legitimate features like Wireless ADB for malicious purposes reflects a broader trend of attackers leveraging built-in functionalities to bypass security measures, emphasizing the importance of cautious permission granting and regular security updates.
2 weeks ago
Kill Chain
Ghostcommit: Unveiling the AI Code Review Exploit via Image-Based Prompt Injection
In July 2026, researchers from the University of Missouri-Kansas City's ASSET Research Group unveiled 'Ghostcommit,' a sophisticated supply chain attack that exploits AI code reviewers by embedding prompt injections within image files. The attack involves submitting a pull request containing a PNG image with hidden instructions that, when processed by AI agents, extract sensitive information from the repository's environment files and encode them into the source code as innocuous-looking data. This method effectively bypasses traditional code review processes, as images are typically not scrutinized for malicious content. The 'Ghostcommit' attack underscores a critical vulnerability in AI-assisted development workflows, highlighting the need for enhanced scrutiny of non-textual assets in code reviews. As AI integration in software development continues to grow, understanding and mitigating such novel attack vectors becomes imperative to maintain the integrity and security of development pipelines.
2 weeks ago
Kill Chain
CISA Adds Two Critical Vulnerabilities to Known Exploited Vulnerabilities Catalog
On July 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-48939 and CVE-2026-56291. CVE-2026-48939 is a critical remote code execution vulnerability in the iCagenda extension for Joomla, allowing unauthenticated attackers to upload and execute arbitrary PHP files on the server. CVE-2026-56291 pertains to the Balbooa Forms extension, enabling similar unauthorized file uploads leading to potential server compromise. Both vulnerabilities have been actively exploited in the wild, posing significant risks to organizations using these Joomla extensions. The inclusion of these vulnerabilities in the KEV Catalog underscores the persistent threat posed by unpatched software components in widely used content management systems. Organizations are urged to prioritize the remediation of these vulnerabilities to prevent potential data breaches and system compromises.
2 weeks ago
Kill Chain
Critical Zimbra Stored XSS Vulnerability Discovered
In July 2026, Zimbra disclosed a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client, allowing attackers to execute arbitrary JavaScript by sending specially crafted emails. This flaw could lead to unauthorized access to mailbox information, session data, or account settings. Zimbra has released updates to address this issue and urges users to upgrade to version 10.1.19 for optimal protection. This incident underscores the persistent threat of XSS vulnerabilities in web applications, emphasizing the need for continuous security assessments and prompt patch management to mitigate potential exploits.
2 weeks ago
Kill Chain
Wireshark 4.6.7: Critical Security Updates Released
On July 8, 2026, Wireshark released version 4.6.7, addressing twelve security vulnerabilities across various protocol dissectors and file parsers. These flaws, present in versions 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16, could allow attackers to crash the application or consume excessive CPU resources by injecting malformed packets or convincing users to open crafted packet trace files. Affected components include Catapult DCT2000, SSH, IEEE 802.11, Z39.50, UMTS FP, pcapng file reader, and DBS Etherwatch file parser. ([wireshark.org](https://www.wireshark.org/news/20260708.html?utm_source=openai)) This release underscores the importance of promptly updating network analysis tools to mitigate potential security risks. The vulnerabilities highlight the need for continuous vigilance in monitoring and updating software to protect against emerging threats.
2 weeks ago
Kill Chain
Squidbleed Vulnerability: A 29-Year-Old Flaw Exposing Sensitive Data in Squid Proxy
In June 2026, security researchers disclosed 'Squidbleed' (CVE-2026-47729), a critical vulnerability in the Squid web proxy that had existed since 1997. This flaw, stemming from an out-of-bounds read in Squid's FTP gateway parser, allows attackers controlling an FTP server to leak sensitive data, including HTTP requests and authentication headers, from users sharing the same proxy. The vulnerability affects all versions of Squid in their default configurations and is particularly concerning in shared environments like corporate networks and public Wi-Fi hotspots. ([hivepro.com](https://www.hivepro.com/threat-advisory/squidbleed-decades-old-parser-flaw-exposes-sensitive-proxy-data?utm_source=openai)) The discovery of Squidbleed underscores the persistent risks posed by legacy code in widely used software. It highlights the necessity for organizations to regularly audit and update their systems to mitigate potential security threats that may have been lurking undetected for decades. ([securityweek.com](https://www.securityweek.com/decades-old-squid-proxy-flaw-squidbleed-can-expose-user-data/?utm_source=openai))
2 weeks ago
Kill Chain
Critical Stored XSS Vulnerability in Zimbra's Briefcase Feature: CVE-2026-33370
In March 2026, a stored cross-site scripting (XSS) vulnerability, identified as CVE-2026-33370, was discovered in Zimbra Collaboration Suite (ZCS) versions 10.0 and 10.1. This flaw resided in the Briefcase feature, where insufficient sanitization of specific uploaded file types allowed attackers to embed malicious JavaScript. When users accessed these compromised files, the scripts executed within their session context, potentially leading to data exfiltration or unauthorized actions. Zimbra promptly addressed this issue by releasing version 10.1.19, urging all users to update their systems to mitigate the risk. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/cve-2026-33370?utm_source=openai)) The discovery of CVE-2026-33370 underscores the persistent threat posed by XSS vulnerabilities in widely used collaboration platforms. Given Zimbra's extensive user base, including numerous businesses and government agencies, timely patching is crucial to prevent potential exploitation. This incident highlights the importance of regular security assessments and prompt software updates to safeguard sensitive information.
2 weeks ago
Kill Chain
Insider Threats: Cybersecurity Experts Turned Cybercriminals
In 2023, three U.S. cybersecurity professionals—Ryan Goldberg, Kevin Martin, and Angelo Martino—exploited their insider knowledge to conduct ransomware attacks using the ALPHV/BlackCat variant. Operating between April and December, they targeted multiple organizations, including a medical device company, a pharmaceutical firm, and a drone manufacturer. The trio encrypted victims' data and demanded substantial cryptocurrency ransoms, successfully extorting approximately $1.2 million from one victim. Their actions culminated in guilty pleas and subsequent prison sentences of four years each. ([justice.gov](https://www.justice.gov/opa/pr/two-americans-who-attacked-multiple-us-victims-using-alphv-blackcat-ransomware-sentenced?utm_source=openai)) This case underscores a disturbing trend where trusted insiders leverage their positions for malicious gain, highlighting the critical need for robust internal security measures and continuous monitoring to detect and prevent such insider threats.
2 weeks ago
Kill Chain
Progress ShareFile SZC Vulnerabilities: A 2026 Security Wake-Up Call
In April 2026, critical vulnerabilities were discovered in Progress Software's ShareFile Storage Zones Controller (SZC), specifically CVE-2026-2699 and CVE-2026-2701. These flaws allowed unauthenticated attackers to access restricted configuration pages and execute arbitrary code on affected systems. Despite the release of patches in March 2026, by July 2026, credible external threats targeting unpatched SZC instances prompted Progress to advise customers to immediately shut down their servers to prevent potential data breaches. This incident underscores the persistent risks associated with unpatched software vulnerabilities, especially in widely used enterprise solutions. Organizations are reminded of the importance of timely patch management and proactive security measures to mitigate evolving cyber threats.
2 weeks ago
Kill Chain
Critical Authentication Bypass in Gitea Docker Image (CVE-2026-20896)
In July 2026, a critical authentication bypass vulnerability, CVE-2026-20896, was discovered in Gitea's official Docker image versions up to and including 1.26.2. This flaw allowed unauthenticated attackers to impersonate any user, including administrators, by exploiting a default configuration that trusted reverse-proxy authentication headers from any source IP address. Exploitation began less than two weeks before public disclosure, with approximately 6,200 Gitea instances exposed on the public web. Successful exploitation granted attackers full access to repositories, CI/CD secrets, and administrative functions, posing significant risks to organizations relying on Gitea for source code management. The rapid exploitation of CVE-2026-20896 underscores the critical importance of promptly addressing default configuration vulnerabilities in widely used open-source tools. Organizations must remain vigilant, ensuring that default settings are reviewed and adjusted to align with security best practices to prevent unauthorized access and potential data breaches.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports